Skip to content
View oshaked1's full-sized avatar

Block or report oshaked1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

πŸ” Forensics and Research Tools

57 repositories

View ETW Provider manifest

C# 450 72 Updated Nov 1, 2024

Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider

C 169 28 Updated Dec 6, 2022

Sysmon-Like research tool for ETW

C++ 350 41 Updated Nov 15, 2022

Adversary tradecraft detection, protection, and hunting

Go 2,265 194 Updated Feb 6, 2025

ELF file viewer/editor for Windows, Linux and MacOS.

C++ 1,412 124 Updated Feb 6, 2025

Volatility Symbol Generator for Linux Kernels

Python 32 6 Updated Nov 15, 2023

AVML - Acquire Volatile Memory for Linux

Rust 903 78 Updated Feb 6, 2025

A wireshark plugin to instrument ETW

Lua 548 58 Updated Jan 28, 2022

A suite of Volatility 3 plugins for memory forensics of Docker containers

Python 18 3 Updated Jan 10, 2024

magic-trace collects and displays high-resolution traces of what a process is doing

OCaml 4,781 96 Updated Nov 22, 2024

High-level tracing language for Linux

C++ 8,895 1,369 Updated Feb 6, 2025

Performance analysis tools based on Linux perf_events (aka perf) and ftrace

Shell 9,998 1,647 Updated Nov 22, 2023

All reasonably stable tools

1,200 237 Updated Aug 17, 2024

Sample ebpf programs to analyze

C 90 12 Updated Dec 18, 2024

bouheki is KRSI(eBPF+LSM) based Linux security auditing tool.

C 87 8 Updated Feb 28, 2023

πŸ” A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

C++ 46,938 2,036 Updated Feb 6, 2025

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

JavaScript 788 83 Updated Oct 5, 2023

Packet, where are you? -- eBPF-based Linux kernel networking debugger

C 3,048 181 Updated Feb 5, 2025

Linux Kernel Runtime Integrity with eBPF

C 172 21 Updated Nov 23, 2023

A Linux Host-based Intrusion Detection System based on eBPF.

C 424 82 Updated Dec 20, 2023

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

C 13,883 1,468 Updated Feb 6, 2025

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

PowerShell 577 61 Updated Nov 24, 2024

You didn't think I'd go and leave the blue team out, right?

1,637 243 Updated Sep 19, 2023

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of U…

Shell 857 130 Updated Feb 5, 2025

Reverse Engineer's Toolkit

Inno Setup 4,877 506 Updated Apr 14, 2024

Open Source EDR for Windows

Go 1,177 144 Updated Feb 25, 2023

Portable Executable reversing tool with a friendly GUI

C++ 2,886 177 Updated Dec 5, 2024

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C 2,102 265 Updated Feb 5, 2025

IDA plugin which queries language models to speed up reverse-engineering

Python 2,950 270 Updated Feb 5, 2025

Windows kernel hacking framework, driver template, hypervisor and API written on C++

C++ 1,691 391 Updated Nov 12, 2023